Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Foundations of IT Security and Secure Coding
- Core principles of application security
- Guidelines for secure software development
- Prevalent security risks in web applications
- The developer's role in preventing vulnerabilities
Essentials of Web Application Security
- Analyzing the attack surface of web applications
- Common techniques used to exploit web services
- Security principles specific to PHP-based systems
- Best practices in the secure development lifecycle
Web Application Vulnerabilities
- Survey of common web security weaknesses
- Strategies for preventing injection attacks
- Methods for mitigating Cross-Site Scripting (XSS)
- Protection against Cross-Site Request Forgery (CSRF)
- Addressing insecure direct object references and access control flaws
- Implementing secure session management
- Considerations for secure file uploads
Secure Input Validation and Data Processing
- The critical need for validating and sanitizing user input
- Blocking the processing of malicious data
- Leveraging PHP validation and filtering capabilities
- Shielding applications from unexpected or harmful input
Client-Side Security
- Identifying security risks within JavaScript
- Securing Ajax request handling
- Addressing HTML5 security concerns
- Preventing common client-side vulnerabilities
- Synchronizing client-side and server-side security measures
Practical Cryptography for PHP
- Basics of cryptographic concepts
- Hashing mechanisms and password protection
- Encryption methods and secure data storage
- Integrating PHP security extensions, including OpenSSL
- Implementing cryptographic best practices
PHP Security Features and Development Techniques
- Overview of PHP security extensions and built-in safeguards
- Utilizing Ctype, ext/filter, and HTML Purifier
- Adopting secure coding patterns in PHP
- Avoiding typical PHP programming errors
- Managing errors and exceptions securely
Hardening the PHP Environment
- Securing PHP configuration parameters
- Recommendations for php.ini security settings
- Apache and server-level security considerations
- Managing file permissions and application configurations
- Safeguarding production environments
Advanced PHP Vulnerability Topics
- Security issues related to time and state
- Understanding open_basedir security implications
- Scenarios involving denial-of-service attacks
- Vulnerabilities arising from hash collisions
- Current security concerns in the PHP framework
Security Testing and Assessment Methods
- Introduction to application security testing
- Deploying security scanners and diagnostic tools
- Principles of penetration testing
- Using proxy tools, sniffers, and fuzzing techniques
- Performing static source code analysis
Practical Secure Coding Workshop
- Analyzing vulnerable PHP codebases
- Implementing mitigation strategies
- Verifying security enhancements
- Reviewing secure coding resources and industry best practices
Requirements
No prior experience is required.
Testimonials (3)
I genuinely enjoyed the real life examples.
Marios Prokopiou
Course - Secure coding in PHP
All topics were well covered and presented with a lot of examples. Ahmed was very efficient and managed to keep us focused and attracted at all times.
Kostas Bastas
Course - Secure coding in PHP
The subject of the course was very interesting and gave us many ideas.